Configuration preset loader for `conventional-changelog`.
78%
Total Score
100
94
67
50
No build attestation or trusted-publisher provenance was detected, so the release's publication origin is less verifiable than it could be.
The project uses TypeScript, Vite, and npm build tooling, but no security-scanning tools were detected, leaving a modest security-process gap.
No repository security policy was found, reducing transparency about vulnerability reporting and response procedures.
All five workflows were analyzed with no high-confidence audit findings or untrusted checkouts, but all 37 action references are unpinned and one workflow has top-level write permissions, creating avoidable workflow-integrity and permission-hygiene risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.